5 ms·
it's fairly well known that small kmallocs do not fail, and that there are many, many instances in the filesystem code which assume that small kmallocs do not f
by Hello71 7y ago
it's fairly well known that small kmallocs do not fail, and that there are many, many instances in the filesystem code which assume that small kmallocs do not fail. there have been two LWN articles on this exact subject.
- girvo 7y agoAnd goto being used for error handling is pretty stock standard across most C codebases I’ve worked on or seen over the years, so I’m not sure what the particular gripe is there
- telanis 7y agoSince when is "we do it all the time" the same as "it's a good thing"?
- tmd83 7y agoI'm not experienced in C or kernel code but from my understanding they use it almost entirely like a catch/finally clause of many higher level language which is a widely accepted and successful pattern.
- __s 7y agoSince when are standard practices the same as "it's a good thing"? Well written code is the best code. Some well written code uses goto. Some not well written code doesn't use goto
- nothrabannosir 7y agogoto for error handling is not just "freeform anything goes goto". It's a very specific idiom, being an "error" label and a bunch of "if (resource) free(resource)" statements at the end of the function. It is essentially analogous to a common use case of Go's defer. Typically an accepted pattern when dealing with many resources and possible exit points. Prevalent in I/O heavy code. Different ballgame from the subject of Dijkstra's manifesto.
- josteink 7y ago> It is essentially analogous to a common use case of Go Go, which is also known for its terrible error-handling. Great.
- neop1x 7y agoReally? I have never seen a Go program to misbehave while not printing some meaningful output. It is possible but almost no one ignores the error parameter. Yet I have seen many, many Java and Python software which quit after the first Unhandled Exception. So often that I consider exceptions as the bad error handling mechanism.
- kevin_thibedeau 7y agoProperly used goto is essentially an inline exception handler. That is a good thing to eliminate repetitive fault checks and fragile cleanup code.
- cjbprime 7y agoIt's both common and a good idea, when used purely internally to a function in order to redirect error paths to a standard set of cleanup code. It helps prevents memory errors and other problems. This is the sense in which the Linux kernel uses goto.
- jumpingmice 7y agoYeah that’s the rumor but allocations of any size can fail when kmem cgroup accounting is enabled and the container is out of space.
- jnurmine 7y agoWell, if the allocation is done with GFP_ACCOUNT bit set, i.e. kmemcg accounting enabled, isn't that the intended behaviour that the allocation can fail?
- jumpingmice 7y agoYes that is the point. In the relatively rare case of failure this particular function uses a goto to return without releasing a held mutex. Error paths within the kernel are a rich vein of malfunction.